Evaluate the complete private-AI configuration before you trust it
Locs evaluates, governs and records the complete private AI configuration before operational use. This page states the controls in plain language — and the current release status and known limitations, honestly.
Data boundary
Raw enterprise data egress is zero by design. The model, documents and answers stay in your environment; air-gap operation is supported.
Enterprise identity
Provider-neutral OIDC with an Entra profile; role-based access enforced in retrieval queries.
Encryption & keys
AES-256-GCM envelope encryption for raw documents; a key inventory with a lifecycle and raw-master rotation. HSM/TPM/Key Vault are documented integration seams.
Tamper-evident audit
Append-only hash-chained audit trail with security events forwarded to SIEM. Tamper-evident — not WORM.
Prompt-injection & output controls
Deterministic input/output controls and dangerous-action refusal. We measure injection resistance in the Assurance Lab; we do not claim perfect protection or zero hallucinations.
Kill switch & recovery
A kill switch blocks AI serving regardless of state; encrypted backup with verified restore drills preserves audit-chain continuity.
Known limitations & customer-onboarding validations
The following are validated in the customer environment during onboarding as explicit, fail-closed go-live gates — they are not shipped claims:
| Item | Status |
|---|---|
| Live Entra login flow | Onboarding gate discovery-level validated internally |
| Live SharePoint / ServiceNow instances | Onboarding gate mock-validated; live per customer |
| BMC Remedy | Adapter only not yet live-validated |
| Customer HA / failover | Onboarding gate durable queue & reconnect validated; multi-replica failover per customer |
| Container / OS image scan | Onboarding gate dependency scans run; image scan in customer CI |
| External penetration test | Planned owner-gated |
| Telecom-SME golden set | Onboarding gate synthetic set today; SME-authored per customer |
| ISO 27001 / ISO 42001 / SOC 2 | Roadmap readiness targets, not certifications |
Full disclosure is maintained in the gap register. Aligned to relevant frameworks; not formally certified.
Get the CISO & architecture pack.
A complete security package: architecture, data flow, identity, encryption, key management, connectors, assurance, threat model, evidence, recovery, known limitations and customer responsibilities.